Skip to content

Releases: MetaMask/core

1314.0.0

Choose a tag to compare

@github-actions github-actions released this 01 Oct 15:54
5c82ed9

@metamask/account-tree-controller 11.0.1

Changed

  • Bump lodash-es from ^4.17.21 to ^4.18.1 (#10447)
  • Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)

@metamask/assets-controllers 112.1.2

Changed

  • Bump @metamask/transaction-controller from ^72.0.1 to ^72.1.0 (#10652)
  • Bump @metamask/network-controller from ^37.0.0 to ^37.0.1 (#10658)
  • Bump @metamask/network-enablement-controller from ^7.0.1 to ^7.0.2 (#10658)
  • Bump @metamask/account-tree-controller from ^11.0.0 to ^11.0.1 (#10662)
  • Bump @metamask/core-backend from ^12.0.0 to ^12.0.1 (#10662)
  • Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)

@metamask/bridge-controller 82.0.2

Changed

  • Bump @metamask/transaction-controller from ^72.0.1 to ^72.1.0 (#10652)
  • Bump @metamask/assets-controller from ^18.0.0 to ^18.0.1 (#10658)
  • Bump @metamask/network-controller from ^37.0.0 to ^37.0.1 (#10658)
  • Bump @metamask/assets-controllers from ^112.1.1 to ^112.1.2 (#10662)
  • Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)

@metamask/bridge-status-controller 76.3.5

Changed

  • Bump @metamask/bridge-controller from ^82.0.0 to ^82.0.2 (#10648, #10662)
  • Bump @metamask/transaction-controller from ^72.0.1 to ^72.1.0 (#10652)
  • Bump @metamask/network-controller from ^37.0.0 to ^37.0.1 (#10658)
  • Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)

@metamask/claims-controller 1.0.3

Changed

  • Bump @metamask/base-data-service from ^2.0.0 to ^2.1.0 (#10502)
  • Bump @tanstack/query-core from ^5.89.0 to ^5.103.2 (#10511)
  • Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)

@metamask/core-backend 12.0.1

Changed

  • Bump @metamask/account-tree-controller from ^11.0.0 to ^11.0.1 (#10662)
  • Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)

@metamask/kyc-controller 0.6.1

Changed

  • Bump @metamask/base-data-service from ^2.0.0 to ^2.1.0 (#10502)
  • Bump @tanstack/query-core from ^5.89.0 to ^5.103.2 (#10511)
  • Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)

@metamask/notification-services-controller 29.0.3

Changed

  • Bump lodash-es from ^4.17.21 to ^4.18.1 (#10447)
  • Bump firebase from ^11.2.0 to ^11.10.0 (#10530)
  • Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)

@metamask/profile-controller 1.0.1

Changed

  • Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)

@metamask/profile-metrics-controller 5.1.3

Changed

  • Bump @metamask/transaction-controller from ^72.0.0 to ^72.1.0 (#10462, #10652)
  • Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)

@metamask/profile-sync-controller 34.0.0

Changed

  • Open the verification session on enrollment and let the server set its lifetime (#10653)
    • completeCredentialEnrollment opens a verification session with the assertion POST /api/v2/mfa/enroll/complete returns for the new credential, replacing any earlier one, so no separate verification is needed right after enrolling. If the token exchange fails, the enrollment still succeeds and the earlier session is kept
    • SRPJwtBearerAuth.completeMfaEnrollment and JwtBearerAuth.completeMfaEnrollment return that assertion
    • The session lasts for the token's expires_in, measured on the device clock, instead of at most 15 minutes
  • Replace JS AES implementation with @metamask/cryptography (#10621)
  • Bump immer from ^9.0.21 to ^11.1.18 (#10382)

Removed

  • BREAKING: Remove VERIFICATION_SESSION_TTL_MS, as the server now sets the verification session lifetime (#10653)

Fixed

  • Coalesce overlapping performSignIn calls so only one sign-in runs at a time (#10646)
  • Rely on @metamask/key-tree crypto implementation for HMAC-SHA-512 instead of hardcoded noble implementation (#10424)
    • @metamask/key-tree uses WebCrypto API if available and fallback to noble otherwise.
    • One note, we expect the platform to provide a fully-compliant WebCrypto (crypto.subtle) implementation for this to work (@metamask/key-tree detection is global and not "per crypto functions").

@metamask/ramps-controller 26.2.0

Changed

  • RampsController.setSelectedToken matches eip155 ERC-20 asset ids case-insensitively and keeps the catalog token's own assetId. Non-EVM asset ids still require an exact match (#10545)
  • Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)

@metamask/shield-controller 7.0.4

Changed

  • Bump @metamask/transaction-controller from ^72.0.0 to ^72.1.0 (#10462, #10652)
  • Bump @metamask/base-data-service from ^2.0.0 to ^2.1.0 (#10502)
  • Bump @tanstack/query-core from ^5.89.0 to ^5.103.2 (#10511)
  • Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)

@metamask/smart-transactions-controller 27.1.0

Changed

  • Expose structured fetch error data (#10494)
  • Export getErrorData util to parse Sentinel API errors (#10642)
  • Bump @metamask/transaction-controller from ^72.0.0 to ^72.1.0 (#10462, #10652)
  • Bump @ethersproject/bytes from ^5.7.0 to ^5.8.0 (#10480)
  • Bump lodash-es from ^4.17.21 to ^4.18.1 (#10447)
  • Bump @ethersproject/transactions from ^5.7.0 to ^5.8.0 (#10483)
  • Bump @metamask/network-controller from ^37.0.0 to ^37.0.1 (#10658)
  • Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)

@metamask/social-controllers 3.6.0

Added

  • Add block, fetchBlockedProfiles, and fetchBlockedContent methods to SocialService (and the matching SocialService:block, SocialService:fetchBlockedProfiles, and SocialService:fetchBlockedContent messenger actions) for the social-api moderation block endpoints (#10656)
    • block calls PUT /moderation/block with exactly one of profileId, commentId, or replyId, plus an optional reason. The endpoint returns 204.
    • fetchBlockedProfiles calls GET /moderation/blocks/profiles and returns traders the caller has blocked, most recently blocked first. Pass cursor from the previous page; cursor is null on the last page.
    • fetchBlockedContent calls GET /moderation/blocks/content and returns comments and replies the caller has blocked, most recently blocked first, with the same cursor pagination.

Changed

  • Bump @metamask/core-backend from ^12.0.0 to ^12.0.1 (#10662)
  • Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)

@metamask/subscription-controller 12.0.1

Changed

  • Bump @metamask/profile-sync-controller from ^33.0.0 to ^34.0.0 (#10662)

1313.0.0

Choose a tag to compare

@github-actions github-actions released this 01 Oct 15:17
384cb02

@metamask/analytics-controller 4.0.0

Changed

  • BREAKING: AnalyticsControllerMessenger requires ConfigRegistryController:getState in its allowed actions and ConfigRegistryController:stateChanged in its allowed events (#10448)
  • Update AnalyticsController.init to listen for ConfigRegistryController state changes and update in-memory event-purpose classification when the version differs (#10448)
  • Add @metamask/config-registry-controller ^4.0.0 as a dependency (#10448)
  • Bump lodash-es from ^4.17.21 to ^4.18.1 (#10447)
  • Bump @metamask/config-registry-controller from ^4.0.0 to ^5.0.0 (#10658)

@metamask/assets-controller 18.0.1

Changed

  • Bump @metamask/transaction-controller from ^72.0.1 to ^72.1.0 (#10652)
  • Bump @metamask/config-registry-controller from ^4.0.0 to ^5.0.0 (#10658)
  • Bump @metamask/network-controller from ^37.0.0 to ^37.0.1 (#10658)
  • Bump @metamask/network-enablement-controller from ^7.0.1 to ^7.0.2 (#10658)

@metamask/config-registry-controller 5.0.0

Added

  • Add ConfigRegistryApiService.fetchEventsConfig, which hits /v1/config/events-config (#10448)

Changed

  • BREAKING: ConfigRegistryControllerMessenger requires ConfigRegistryApiService:fetchEventsConfig in its allowed actions (#10448)
  • ConfigRegistryController now caches the result from /v1/config/events-config in configs.eventsConfig in its polling loop (#10448)
  • Bump @metamask/utils from ^11.12.0 to ^12.0.0 (#10192)
  • Bump @metamask/keyring-controller from ^28.0.0 to ^28.1.0 (#10418)

@metamask/network-controller 37.0.1

Changed

  • Bump uuid from ^8.3.2 to ^11.1.1 (#10117, #10243)
  • Bump @metamask/utils from ^11.12.0 to ^12.0.0 (#10192)
  • Bump immer from ^9.0.6 to ^11.1.18 (#10331, #10382)
  • Bump @metamask/analytics-controller from ^3.0.0 to ^4.0.0 (#10301, #10411, #10658)
  • Bump @metamask/config-registry-controller from ^4.0.0 to ^5.0.0 (#10658)

@metamask/network-enablement-controller 7.0.2

Changed

  • Bump @metamask/transaction-controller from ^72.0.0 to ^72.1.0 (#10462, #10652)
  • Bump @metamask/config-registry-controller from ^4.0.0 to ^5.0.0 (#10658)
  • Bump @metamask/network-controller from ^37.0.0 to ^37.0.1 (#10658)

@metamask/wallet 16.0.1

Changed

  • Bump @metamask/config-registry-controller from ^4.0.0 to ^5.0.0 (#10658)
  • Bump @metamask/network-controller from ^37.0.0 to ^37.0.1 (#10658)

1312.0.0

Choose a tag to compare

@github-actions github-actions released this 01 Oct 12:48
419725e

@metamask/subscription-controller 12.0.0

Added

  • BREAKING: Add SubscriptionController:isUserEligibleForTrial to report whether a user can start a trial for a product (#10622)
    • Clients must grant SubscriptionControllerMessenger access to SeedlessOnboardingController:getIsUserAuthenticated in order to call SubscriptionController:isUserEligibleForTrial.

Changed

  • Bump @metamask/money-account-balance-service from ^3.1.1 to ^3.1.2 (#10624)
  • Bump @metamask/chomp-api-service from ^6.0.0 to ^6.0.1 (#10626)
  • Bump @metamask/transaction-controller from ^72.0.1 to ^72.1.0 (#10652)

@metamask/wallet 16.0.0

Changed

  • BREAKING: Grant SubscriptionController access to SeedlessOnboardingController:getIsUserAuthenticated (#10622)
    • Clients must delegate this action to the Wallet messenger.
  • BREAKING: Wire up ConfigRegistryApiService:fetchEventsConfig action handler in configRegistryController initialization (#10448)
    • The messenger passed to Wallet must support this action.
  • Bump @metamask/transaction-controller from ^72.0.1 to ^72.1.0 (#10652)
  • Bump @metamask/subscription-controller from ^11.0.0 to ^12.0.0 (#10655)

1311.0.0

Choose a tag to compare

@github-actions github-actions released this 01 Oct 11:44
837f672

@metamask/cryptography 1.1.0

Added

  • Add an additionalData option to AES-GCM encrypt and decrypt (#10628)
  • Allow HKDF functions to derive from an empty input when unsafeInputKeyingMaterial is set (#10628)

Fixed

  • Narrow return type for AES encrypt function to Uint8Array<ArrayBuffer> (#10623)

@metamask/transaction-controller 72.1.0

Changed

  • Include a RedeemerEnforcer caveat in EIP-7702 gas fee token simulations via suggestFees.withRedeemerEnforcer (#10615)

  • Bump ethereum-cryptography from ^2.1.2 to ^2.2.1 (#10485)

  • Bump lodash-es from ^4.17.21 to ^4.18.1 (#10447)

  • Bump @ethersproject/wallet from ^5.7.0 to ^5.8.0 (#10484)

  • Bump @metamask/core-backend from ^11.0.0 to ^12.0.0 (#10648)

1310.0.0

Choose a tag to compare

@github-actions github-actions released this 01 Oct 10:28
dd48fd3

@metamask/assets-controller 18.0.0

Added

  • BREAKING: AssetsControllerMessenger now requires the MultichainTransactionsControllerTransactionConfirmedEvent allowed event (#10585)
    • AssetsController subscribes to MultichainTransactionsController:transactionConfirmed so non-EVM (Snap keyring) transactions trigger the same post-transaction balance refresh as EVM TransactionController:transactionConfirmed.
    • Consumers must delegate MultichainTransactionsController:transactionConfirmed onto the Assets controller messenger. Without that delegation the subscription is registered and never fires.

Changed

  • Bump lodash-es from ^4.17.21 to ^4.18.1 (#10447)
  • Bump @ethersproject/providers from ^5.7.0 to ^5.8.0 (#10482)
  • Bump @metamask/assets-controllers from ^112.0.4 to ^112.1.1 (#10633, #10648)
  • Bump @metamask/phishing-controller from ^18.1.1 to ^18.2.0 (#10633)
  • Bump @metamask/core-backend from ^11.0.0 to ^12.0.0 (#10648)

Fixed

  • Fix PriceDataSource supported-network filtering so it reads the object-shaped partialSupport returned by the Price API /v2/supportedNetworks endpoint (#10582)
  • On the v5 balance path, stop seeding every enabled chain's native onto an account when the update arrives after that account is no longer selected (#10567)
  • On unlock, drop stored balances whose chain namespace is outside the selected account's scopes (#10567)

@metamask/assets-controllers 112.1.1

Changed

  • Bump @metamask/core-backend from ^11.0.0 to ^12.0.0 (#10648)

@metamask/bridge-controller 82.0.1

Changed

  • Bump @metamask/assets-controller from ^17.0.0 to ^18.0.0 (#10648)
  • Bump @metamask/assets-controllers from ^112.1.0 to ^112.1.1 (#10648)

@metamask/client-utils 3.0.4

Changed

  • Bump eth-chainlist from ^0.0.795 to ^0.0.844 (#10438, #10524)
  • Bump @metamask/transaction-controller from ^72.0.0 to ^72.0.1 (#10462)
  • Bump @metamask/core-backend from ^11.0.0 to ^12.0.0 (#10648)

@metamask/core-backend 12.0.0

Changed

  • BREAKING: PriceSupportedNetworksResponse now matches the real /v2/supportedNetworks response, with partialSupport typed as { spotPricesV2: string[]; spotPricesV3: string[] } instead of string[] (#10582)
  • Bump uuid from ^9.0.1 to ^11.1.1 (#10243)
  • Bump @metamask/profile-sync-controller from ^32.1.1 to ^33.0.0 (#10348, #10409, #10418, #10459)
  • Bump @tanstack/query-core from ^5.62.16 to ^5.103.2 (#9324, #10511)
  • Bump @metamask/keyring-controller from ^28.0.0 to ^28.1.0 (#10418)
  • Bump cockatiel from ^3.1.2 to ^3.2.1 (#10436)
  • Bump @metamask/account-tree-controller from ^10.0.1 to ^11.0.0 (#10459)

Deprecated

  • Deprecate PriceSupportedNetworksResponse in favor of PriceV2SupportedNetworksResponse (#10582)

@metamask/social-controllers 3.5.0

Added

  • Add SocialRealtimeService for subscribing to Social realtime feed events through the shared backend WebSocket connection (#10561)

Changed

  • Bump @metamask/base-data-service from ^2.0.0 to ^2.1.0 (#10502)
  • Bump @metamask/core-backend from ^11.0.0 to ^12.0.0 (#10648)

@metamask/transaction-pay-controller 30.0.1

Changed

  • Bump @metamask/ramps-controller from ^26.0.1 to ^26.1.0 (#10569)
  • Bump @metamask/assets-controller from ^17.0.0 to ^18.0.0 (#10648)

1309.0.0

Choose a tag to compare

@github-actions github-actions released this 01 Oct 08:21
ebdd04c

@metamask/bridge-controller 82.0.0

Changed

  • BREAKING: Rename recurring_buy FeatureId to recurring_order (#10631)
  • Bump @metamask/assets-controllers from ^112.0.4 to ^112.1.0 (#10633)

@metamask/bridge-status-controller 76.3.4

Changed

  • Bump @metamask/bridge-controller from ^81.3.3 to 82.0.0. (#10580, #10641)

1308.0.0

Choose a tag to compare

@github-actions github-actions released this 30 Sep 21:55
f5713f2

@metamask/profile-controller 1.0.0

Added

  • Add ProfileController for managing user profile state, exposing getMetaMaskProfile, getXprofile, createProfile, replaceProfile, updateProfile, deleteProfile, checkUsernameAvailability, getXAuthUrl, connectX, and getXAccount via the messenger (#10558)
  • Add ProfileService for communicating with the MetaMask Profile API, exposing getProfile, createProfile, replaceProfile, updateProfile, deleteProfile, checkUsernameAvailability, getXAuthUrl, connectX, and getXAccount via the messenger, with superstruct validation on all inputs and responses (#10558)

1307.0.0

Choose a tag to compare

@github-actions github-actions released this 30 Sep 19:54
066a2a1

@metamask/assets-controllers 112.1.0

Added

  • Add optional securityData property to RwaToken, populated when includeTokenSecurityData is requested (#10542)
  • Add optional includeTokenSecurityData property to FetchRwasParams (#10542)

Changed

  • Bump immer from ^9.0.21 to ^11.1.18 (#10382)

  • Bump @metamask/transaction-controller from ^72.0.0 to ^72.0.1 (#10462)

  • Bump @ethersproject/bignumber from ^5.7.0 to ^5.8.0 (#10479)

  • Bump lodash-es from ^4.17.21 to ^4.18.1 (#10447)

  • Bump @ethersproject/providers from ^5.7.0 to ^5.8.0 (#10482)

  • Bump @ethersproject/address from ^5.7.0 to ^5.8.0 (#10478)

  • Bump @tanstack/query-core from ^5.89.0 to ^5.103.2 (#10511)

  • NftController now attributes its PhishingController:bulkScanUrls calls to the nft-detection request source, so NFT metadata URL scans are distinguishable from other callers in phishing-detection service metrics (#10357)

  • Bump @metamask/phishing-controller from ^18.1.1 to ^18.2.0 (#10633)

@metamask/phishing-controller 18.2.0

Added

  • Add optional request-source attribution parameters to PhishingController.scanUrl and bulkScanUrls, emitting an x-request-source header. (#10357)

Changed

  • Bump @types/punycode from ^2.1.0 to ^2.1.4 (#10441)
  • Bump punycode from ^2.1.1 to ^2.3.1 (#10441)
  • Bump @metamask/transaction-controller from ^72.0.0 to ^72.0.1 (#10462)
  • Bump ethereum-cryptography from ^2.1.2 to ^2.2.1 (#10485)

1306.0.0

Choose a tag to compare

@github-actions github-actions released this 30 Sep 16:51
df1a068

@metamask/chomp-api-service 6.0.1

Changed

  • Bump @tanstack/query-core from ^5.89.0 to ^5.103.2 (#10511)

Fixed

  • Ignore unrecognised intent types returned by the CHOMP API instead of failing to parse the whole response (#10609)
    • getIntentsByAddress now omits intents whose metadata.type is not a known ChompIntentType.
    • getServiceDetails now omits unknown values from each protocol's intentTypes.

1305.0.0

Choose a tag to compare

@github-actions github-actions released this 30 Sep 14:04
e4ea4ae

@metamask/money-account-balance-service 3.1.2

Fixed

  • Stop including balance amounts in MoneyAccountBalanceValidationError messages, which are reported via the messenger's captureException (#10619)